Home » Crypto Wallets Targeted by Sophisticated Malware Campaign

Crypto Wallets Targeted by Sophisticated Malware Campaign

12.04.2025 19:00 2 min. read Alexander Stefanov
SHARE: SHARES
Crypto Wallets Targeted by Sophisticated Malware Campaign

Cybersecurity researchers are sounding the alarm after discovering a new and increasingly sophisticated attack targeting the crypto community.

This wave of cyberattacks uses a deceptive software supply chain to target popular Web3 wallets, including Atomic Wallet and Exodus, exploiting vulnerabilities in the npm package manager commonly used by JavaScript and Node.js developers.

The attack centers around a malicious package, pdf-to-office, which masquerades as a tool for converting PDF documents into Microsoft Office formats. However, once downloaded and executed, the package quietly inserts harmful code into the victim’s system, specifically altering locally installed versions of trusted crypto wallets like Atomic Wallet and Exodus.

This code then enables attackers to secretly intercept and reroute cryptocurrency transactions to wallets they control, all while the victim remains unaware.

What makes this attack particularly insidious is its subtlety. Rather than attacking open-source repositories directly, the attackers target existing, legitimate software installations by modifying them locally. This technique is harder to detect and more difficult to counter than traditional supply chain attacks that affect upstream code.

The malicious pdf-to-office package first appeared on npm in March 2025 and has been updated multiple times, with the latest version released in April. Using machine learning analysis, ReversingLabs researchers uncovered the malicious behavior, revealing that the package contained obfuscated JavaScript—an unmistakable sign of a malware campaign.

Even after users removed the malicious package, the damage persisted. The malicious patches remained in the Web3 wallet software, requiring victims to fully uninstall and reinstall their wallet applications to eliminate the trojan and restore security. This attack highlights the evolving nature of cyber threats in the crypto space, requiring heightened vigilance from both developers and users.

With over 8 years of experience in the cryptocurrency and blockchain industry, Alexander is a seasoned content creator and market analyst dedicated to making digital assets more accessible and understandable. He specializes in breaking down complex crypto trends, analyzing market movements, and producing insightful content aimed at educating both newcomers and seasoned investors. Alexander has built a reputation for delivering timely and accurate analysis, while keeping a close eye on regulatory developments, emerging technologies, and macroeconomic trends that shape the future of digital finance. His work is rooted in a passion for innovation and a firm belief that widespread education is key to accelerating global crypto adoption.

Telegram

SHARE: SHARES
More Crypto Crime News
No Comments yet!

Your Email address will not be published.